Intel

AIKIDO-2026-67396

cowlib is vulnerable to Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or ThrottlingCVE-2026-59248 Published 4 days ago

87

High Risk

This Affects:

ELIXIRcowlib
2.0.0 - 2.18.0
Fixed in 2.19.0
Are you affected? Scan for Free

TL;DR

cowlib contains an uncontrolled resource consumption vulnerability in its HPACK and QPACK integer decoder. An unauthenticated attacker can send specially crafted HTTP/2 or HTTP/3 header fields containing excessively long prefixed integers, causing excessive memory allocation and garbage collection due to inefficient bignum processing. Repeated requests can exhaust server memory and lead to a denial of service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

cowlib is vulnerable to Allocation of Resources Without Limits or Throttling in versions 2.0.0 - 2.18.0.

How to fix this

Upgrade the cowlib library to the patch version.